4 ms·
Alternate title: guide to changing your single factor authentication from "something you know" to "something you have."
by naturalpb 6y ago
Alternate title: guide to changing your single factor authentication from "something you know" to "something you have."
- jasonpeacock 6y ago"Something you have" is generally an improvement over "something you know" for most people's account security. You have to remember where we are starting from - most people are still using the same password across all their accounts.
- 1_player 6y agoHow is that? Everybody living in my house can get my Yubikey yet doesn't know my password. If I get robbed, my bank account is still (relatively) safe.
- coder543 6y agoPlaying advocate for the idea: There are a lot more people far away from you than there are close to you. If breaking your security requires physical proximity (such as to steal a yubikey), then you are much safer just based on this. It's also easier for people to blindly steal credentials for millions of people online than it is for them to steal millions of physical security keys. Alternatively, passwords are commonly reused across websites, so a failure of any of those websites can lead to a compromise of all of them, which is not the case with a YubiKey. Along that same line of thought, passwords are phishable, where YubiKeys are not. It's also possible that people in your physical proximity could shoulder surf your password, install a keylogger (which could be a physical keylogger, if you normally use a USB keyboard, not just software), or use a strategically positioned camera to do some digital shoulder surfing. Passwords aren't immune to trust issues when it comes to physical proximity. Ideally, you trust those you are near to some extent. YubiKey also has a fingerprint-protected device coming out soon[0]... which would raise the bar for the threat model in this discussion some. Using a fingerprint and/or PIN to unlock a YubiKey preserves most of the benefits, while eliminating most of the concerns that people are mentioning. HSMs can choose to self-erase after a certain number of failed PIN attempts, so even a short PIN is not something that can easily be brute forced without an unpatched vulnerability. If websites would allow you to only use any one of your YubiKeys to authenticate (obviously meaning you can have multiple, with backup YubiKeys stored somewhere safe in case you lose your main one), I think that would be a significant improvement in security over password authentication for most people. This is basically what the WebAuthn standard is attempting to do. I don't expect most people to be interested in buying 3 security keys and carrying one around all the time, though. [0]: https://www.yubico.com/blog/yubico-reveals-first-biometric-yubikey-at-microsoft-ignite/ https://www.yubico.com/blog/yubico-reveals-first-biometric-y...
- freeone3000 6y agoFor the last bit: If it's suitably seamless, it's actually not that bad. I've been carrying one on my keyring, and it's just another key, only this one "unlocks" websites.
- jasonpeacock 6y agoMost people in your home are not trying to hack you. A lot of people outside your home are trying to hack you. Shifting your exposure from "everyone in the world with an internet connection" to "people who are in/near your home" greatly reduces your risk, objectively.
- naturalpb 6y agoMost people won't purchase and use a Yubikey either though. Really just depends on your threat model, if remote attacks or local attacks are of higher risk. An obvious improvement would be the use of both a password and physical security token.
- nly 6y agoI think you mean from "something you can forget" to "something you can lose"
- dheera 6y agoThis is why "something you have" should be ALWAYS replaced by "one of a few things you have" where you report/deactivate any lost things.
- ozim 6y agoI don't remember like 98% or 99% of my passwords. I have something like 270 on my private accounts and probably 300 passwords on my work accounts. Well password manager is useful and I can always use pw reset option built in systems. I kindly propose everyone to forget all their passwords. Then they mostly don't need second factor if they generate random password each time and don't care about remembering them at all.
- dwaite 6y agoCurrent Yubikeys support multi-factor, both knowledge and possession. It is just up to websites to request this. They have a key coming (some day) which will also support a biometric factor.